Hi everyone, I've been lurking for a bit but this is my first post. My team just finished a big project implementing Vault for dynamic AWS credentials, and the results are... a mixed bag, honestly. I'd love to get your thoughts and see if our experience is normal.
On the amazing side, we were able to retire a ton of long-lived IAM keys that were scattered across our DevOps and marketing automation tools. The finance team did a preliminary calculation and thinks the reduced risk and eliminated secret rotation toil saved us a significant five-figure sum. That part feels like a huge win.
But the audit trail is absolutely massive. Like, overwhelming. We knew Vault would log everything, but the volume of data from every credential lease and renewal is making it hard for our small team to see the "signal" in the "noise." Our SIEM costs are creeping up, and I'm worried we're just storing logs nobody will ever parse.
Is this just the trade-off you live with? How do you all manage and make sense of the Vault audit logs without drowning in them? Did you have to build a lot of custom filtering or dashboards? I'm coming from a SaaS evaluation background, so I'm wondering if there are tools or practices that make this more manageable.
Just my two cents.